Privacy Policy
Last updated: 25 September 2026
Stopa ("we", "us", "the app") is an iOS application that takes a training plan you already have and pushes the workouts to your watch. This Privacy Policy explains what data we collect, why, where it is stored, and the choices you have. We collect the minimum we need to make the app work, and we do not sell your data or use it for advertising.
If you have any questions, contact us at hello@stopa.app.
Who we are
Stopa is built and operated independently from Czechia (European Union). For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is the operator of Stopa, reachable at hello@stopa.app.
What data we collect
We collect only what is needed to deliver the app's core function — importing your training plan and syncing it to your Apple Watch.
Account data. When you sign in with Apple, we receive a Stopa-specific identifier and, if you choose to share it, your email address and name. We use Apple Sign-In as the only sign-in method; we never see or store your Apple password.
Training plans you import. The plan text, files, or pasted content you bring into Stopa, and the structured workouts we derive from it (titles, dates, durations, distances, targets, and any notes you add).
Health & fitness data (Apple Health). With your explicit permission, Stopa reads completed workouts from Apple Health to match them against your planned workouts and to build your training diary. Depending on the activity, this can include workout type, start time, duration, distance, average heart rate, pace, and power. With a Pro subscription, Stopa also reads your older workout history beyond the current training plan when you open past months in your diary, so your diary and your monthly and yearly statistics cover past seasons. For those historical sessions Stopa stores the totals — type, date, duration, distance and the pace derived from them — and reads heart rate or power for one of them only when you open that session's detail. If you create a story — a trip, a training camp or a whole block kept together — Stopa also reads your sleep and resting heart rate for the days that story covers, so it can show how your body responded over that stretch. Those readings are used on that screen and are not stored on our servers: they are read from Apple Health each time you open the story and stay on your device. Stopa's access to Apple Health is read-only — we never write to Apple Health.
Photos you share. You add photos through Apple's system photo picker, which hands Stopa only the images you choose — the app never gets access to your photo library, and never asks for it. A photo you add while sharing is saved to that workout session, exactly like a photo you add on the session itself (see the next paragraph). The analysis that decides where to place your route so it does not cover a face runs entirely on your device. The finished image or video is made on your device and goes only where you choose to send it.
Photos you add to a session or a story. These are different, and we want to be exact about it. If you attach photos to a workout session or to a story, they are uploaded to our servers — that is the only way they can still be there on a new phone or after reinstalling. What is uploaded is a smaller copy, not your original: Stopa resizes the image on your device and re-encodes it, which removes the metadata your camera attached — including the location where the photo was taken. Your original never leaves your phone. Stored photos are private to your account, are not publicly reachable by any link, and are shown to you through short-lived, signed access. Deleting a photo, deleting the story or a session you logged by hand, or deleting your account removes them from our servers.
Basic diagnostics. If the app crashes, we receive a crash report (stack trace and device/OS version) to fix the problem. Crash reports are scrubbed of personal content — we do not include your health values, plan content, or email in them.
We do not collect your location, contacts, browsing history, or advertising identifiers.
How we use your data
- To authenticate you and keep you signed in.
- To parse your imported plan into structured workouts and schedule them on your Apple Watch.
- To match completed Apple Health workouts against your planned workouts so you can see your progress.
- To show your training diary and your training statistics — the sessions you completed, on the days you completed them.
- To diagnose and fix crashes.
We use your data for app functionality only. We do not use it for marketing, profiling, or advertising, and we do not track you across other apps or websites.
How your plan is processed (AI parser)
To turn a free-form plan into structured workouts, Stopa uses a two-step parser that runs on our backend. Most plans are handled by deterministic pattern matching. When part of a plan is ambiguous, that portion of the plan text may be sent to Anthropic's Claude API to interpret it. Only the relevant plan text is sent for this purpose — never your health data, email, or account identifiers. Anthropic processes this text to return structured output and does not use it to train their models.
The coach chat (AI)
Stopa includes an optional in-app coach chat. It is off until you opt in: before your first message, a consent screen explains exactly what is shared, and nothing leaves your device before you agree.
When you send the coach a message, Stopa sends your training plan, your workout history and reflections (RPE, feel, notes), and training metrics derived from Apple Health (distances, durations, paces, heart rate) together with your message to Anthropic's Claude API, so the coach can answer you and propose plan changes. This data is:
- never used to train AI models (Anthropic does not train on API inputs), and
- never stored on our servers — your conversation exists only on your device. Signing out or deleting your account removes it.
Our backend keeps only aggregate, content-free telemetry about coach usage (token counts, timings, and the names of proposed change types) to operate the service — never your messages, your plan text, or your health data.
The coach can propose changes to your plan (add, move, edit, or delete workouts; revise weeks; log how a session went). No proposal is ever applied without you explicitly tapping Apply on the review card.
Where your data is stored
Your account, plan data and any session or story photos are stored using Supabase, hosted in the European Union (Frankfurt, Germany). Data is encrypted in transit (HTTPS/TLS) and at rest. Access is restricted by per-user database security rules so that you can only access your own data.
Apple Health
Health data accessed from Apple Health is used to show you your training progress inside Stopa and — only if you opt in to the coach chat — to let the coach answer your questions (see “The coach chat (AI)” above). In line with Apple's requirements:
- We never use Apple Health data for advertising or marketing.
- We never sell Apple Health data or share it with data brokers.
- We only read the workout data needed to match your sessions and to show your own training diary and statistics, plus sleep and resting heart rate for the days a story covers.
- Sleep and resting heart rate are never stored on our servers — they are read from Apple Health on your device each time you open a story.
You can review or revoke Stopa's Health permissions at any time in Settings → Health → Data Access & Devices → Stopa on your iPhone.
Third-party watch and fitness services
If you choose to connect a third-party watch or fitness service, Stopa will, at your request, send your planned structured workouts to that service so they appear on your watch, and read back your completed activities to match them against your plan. We share only the data needed for this — your scheduled workouts, and activity summary metrics (date, sport, distance, duration, average heart rate and pace) — never your account credentials. The connection uses the provider's secure authorisation (OAuth); access tokens are stored encrypted on our backend, are never placed on your device, and are revoked when you disconnect the service or delete your account. Each provider's own privacy policy governs how they handle your data once it reaches them. This applies only if you actively connect such a service; by default Stopa syncs only to your Apple Watch.
Your rights
You can, at any time:
- Access and export your data by contacting hello@stopa.app.
- Delete your account and data directly in the app via Settings → Account → Delete account. This permanently removes your plans, workouts, and notes from our database.
- Withdraw permissions (Apple Health, notifications) in iOS Settings.
Under GDPR you also have the right to rectification, restriction, objection, and to lodge a complaint with your local data protection authority.
Data retention
We keep your data for as long as your account is active. When you delete your account, your training data is removed from our database and any session or story photos are removed from our file storage. Deleting a single photo, a whole story or a session you logged by hand removes those photos immediately. Crash reports are retained for a limited period for debugging and then discarded.
Children
Stopa is not directed at children. You must be at least 13 years old (or the minimum age of digital consent in your country) to use the app.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by the "Last updated" date at the top of this page.
Contact
Questions about privacy or your data: hello@stopa.app.